Sam Gordon Shield Logo

Defense Industrial Base Security

Sam Gordon

GRC Lead  •  SOC Analyst  •  Incident Responder

Huntsville, AL  //  DIB MSP  //  7 Years Experience

SECURITY+//NETWORK+//CYSA+//CSAP//ISC2 CC

0+
DIB Clients
0+
Incidents / Year
0
SPRS Score
0yr
Experience
Sam Gordon — Cybersecurity Professional Available
// 01 — About

Security Professional

Information security and IT professional with seven years at a Defense Industrial Base (DIB) focused Managed Service Provider, progressing from sole help desk technician supporting roughly 20 client organizations to concurrent GRC Lead and Help Desk Team Lead across a 40+ client portfolio.

Experience spans Security Operations Center (SOC) operations, incident response, Security Information and Event Management (SIEM) administration, vulnerability management, Microsoft 365 and Entra ID administration, firewall and VPN management, and NIST 800-171 and CMMC 2.0 compliance.

Maintains an enterprise-inspired home lab and actively develops threat hunting and detection engineering skills through Josh Madacore's Cyber Range. Holds CompTIA Security+, Network+, CySA+, CSAP, and ISC2 Certified in Cybersecurity (CC) certifications.

SOC Operations Incident Response SIEM / Wazuh CMMC 2.0 NIST 800-171 Threat Hunting BEC Investigation GRC Lead
// 02 — Experience

Work History

Cyburity Huntsville, AL · 2019 — Present
Current Role · Huntsville, AL
GRC Lead & Help Desk Team Lead
Jan 2026 — Present
  • Lead NIST 800-171 and CMMC 2.0 self-assessments across 40+ DIB clients, driving POA&M development and tracking remediation toward full compliance.
  • Engineer technical controls to achieve 110-point SPRS scores, translating NIST 800-171 requirements into operational implementations.
  • Investigate, triage, escalate, and remediate 30+ cyber incidents annually, including BEC cases with CalPhish indicators, Sophos URL rewriting analysis, and Exchange Admin Center forensics.
  • Administer email security controls across client tenants — DMARC/DKIM/SPF enforcement, anti-phishing policies, and user-reported phishing workflows — reducing successful phishing incidents by 70%.
  • Lead help desk team managing 100+ tickets per week while concurrently holding GRC Lead responsibilities across a 40+ client portfolio.
Concurrent Role · Huntsville, AL
Cyber Analyst & System Administrator
Aug 2021 — Present
  • Built and matured security operations capabilities across the client base, including SIEM deployment (Wazuh), vulnerability management, and incident triage workflows.
  • Served as primary Tier 2/Tier 3 technical escalation point for junior engineers, resolving complex system, application, and authentication issues.
  • Administered Microsoft 365 tenants for 40+ DIB clients — Exchange Online, Teams, SharePoint, Entra ID integrations, and Conditional Access policies.
  • Managed firewall rules, VLAN segmentation, and pfSense configurations to enforce least-privilege access and limit lateral movement across client sites.
  • Configured secure SFTP on Synology NAS through pfSense for CUI file transfer use cases involving government contractor clients.
Foundational Role · Huntsville, AL
Help Desk Technician
Aug 2019 — Aug 2021
  • Served as sole help desk technician supporting approximately 20 client organizations, establishing foundational SOPs, ticketing workflows, and escalation procedures from the ground up.
  • Diagnosed and resolved complex hardware, software, networking, and user access issues across Windows, Linux, and Microsoft 365 environments.
  • Onboarded and offboarded users across multiple client tenants, managing provisioning, access control, and secure data handling aligned with least-privilege principles.
// 03 — Skills & Certifications

Technical Profile

SIEM & Detection
WazuhMicrosoft SentinelKQLLog AnalysisThreat HuntingSplunkDetection Engineering
Incident Response
Incident TriageBEC InvestigationPhishing AnalysisIR PlaybooksExchange ForensicsCalPhish
Compliance & GRC
NIST 800-171CMMC 2.0POA&MSPRSDFARSFARRMF
Cloud & Identity
Microsoft 365Entra IDActive DirectoryConditional AccessExchange OnlineMicrosoft Defender
Network & Infrastructure
pfSenseUniFiVLAN SegmentationVPNDMARC/DKIM/SPFFirewall Admin
Frameworks & Scripting
MITRE ATT&CKOWASP Top 10PowerShellBashProxmoxLinux
Active Certifications
Sec+
CompTIA Security+
CompTIA • Expires Dec 2028
Active
CySA
CompTIA CySA+
CompTIA • Expires Dec 2028
Active
Net+
CompTIA Network+
CompTIA • Expires Apr 2029
Active
CSAP
CSAP Stackable
CompTIA • Expires Dec 2028
Active
CC
Certified in Cybersecurity
ISC2 • Expires Dec 2028
Active
// 04 — Projects & Lab

Home Lab & Projects

01
Enterprise Home Lab

Designed and deployed an enterprise-grade segmented network with defense-in-depth principles. Architected multiple VLANs isolating trust zones with firewall-enforced least-privilege, GeoIP filtering, VPN, and centralized SIEM logging.

ProxmoxWazuhpfSenseUniFiVLAN
02
Cyber Range — Threat Hunting

Active participation in Josh Madacore's Cyber Range — simulating attacks, scanning for and remediating vulnerabilities, and conducting threat hunts against realistic Azure VM telemetry using KQL and MITRE ATT&CK tradecraft.

SentinelKQLMITRE ATT&CKNessusAzure
03
IR Documentation Suite

Authored a reusable IR documentation suite for MSP use: Network Outage Report template, Incident Response Report template, and an AI-assisted IR prompt for consistent post-incident artifact generation across security operations.

IR PlaybooksSOPsDocumentationAI-Assisted
// 05 — Education

Academic Background

Bachelor of Science — Computer Science
University of Alabama in Huntsville
Huntsville, Alabama
B.S.
Comp Sci
// 06 — Contact

Let's Connect



Currently open to SOC Analyst and Cyber Analyst opportunities. Particularly interested in roles supporting Defense Industrial Base clients or federal security environments.

[email protected]

Open to Opportunities — SOC / Cyber Analyst